ticklemyIP It falls on the "attacker already knows your password by whatever means" side. Users have terrible shitty passwords all the time, while they can still use TOTP.
I agree, which is why I find it to be simply staggering to say that TOTP provides no security benefits even in events such as leaked/hacked login information. In such events, even a randomised 100+ character password loses its strength of security and an extra barrier would obviously prove beneficial.